• ChaoticNeutralCzech@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      5 days ago

      It’s easier to take precautions though. You probably don’t have an insulated USB port or throwaway host device but handling QR codes safely just takes basic tech and skill.

      Important advice:

      • Don’t use apps that auto-open URLs in QR codes when pointed at!
      • Make sure the app shows the full content of the QR code and lets you peruse it indefinitely before you open the link!
      • Know the structure of URLs and common pitfalls!

      Recommendations:

      • Be extra suspicious if there is no URL printed next to the code, or if the printed URL is different.
      • Use an open source reader app that does not resolve Punycode (Unicode in TLDs).
      • Strip any tracking parameters you spot before following any URLs.
      • Be careful if the QR code could have been easily tampered with (on a sticker over the original one, or on a plain sheet of paper inserted into a plastic wrap together with the rest)

      I think today’s generation’s equivalent is free Wi-Fi networks. Kids without mobile data in an area without an established public network will connect to just about any open one unless the SSID includes “LaserJet” or similar.

      • tiredofsametab@fedia.io
        link
        fedilink
        arrow-up
        0
        ·
        5 days ago

        I keep meaning to look more into how qr codes work. I always wondered if there were possible attack vectors if a bad actor exploited a flaw in the decoding of the image. My mind went to a zip bomb for no apparent reason (a tiny file that unzips to a massive amount of data on disk)

        • ChaoticNeutralCzech@feddit.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          5 days ago

          That is very decoder-specific. The most common QR reader apps are the Camera app on iPhones and Google Lens for Android so you’ll want to target one of these (though Google Lens might be using cloud processing for that). There probably won’t be any exploits in the image processing part but you obviously can write arbitrary data (including ASCII control characters such as CR, LF, null) into the “data” part of the QR code, as the encoding mode and data length is stored in the first 4+(n*8) bits of where data would be instead of null byte termination. Normally, the data is then right-padded with repeating 0xEC11 (or not) and then error correction follows (number of bytes in the error-correction part is defined by the size and ECC mode indicated in another region).

  • NegativeInf@lemmy.world
    link
    fedilink
    arrow-up
    30
    arrow-down
    6
    ·
    6 days ago

    Absolute insanity.

    I would have abused this great and terrible power in just the same way he described. Random orders for random tables at random restaurants at random times in small quantities for as long as they aren’t protected. Just enough to be an inconvenience/awkward but not enough to raise alarms.

    And now I will check every QR code I scan at a restaurant.

    • Psychodelic@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      5 days ago

      That seems kinda fucked up. Why would you do something like that?

      I mean, I at least get fucking with people for money. Doing it for fun, not so much

      Also, anyone know what they meant with this line?

      I still loved my life so I didn’t want to use the Google custom search API.

      • NegativeInf@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        3
        ·
        edit-2
        5 days ago

        Because you can or to prove a point.

        As to the quoted text, I assumed it was a reference to not getting more deeply involved in it that would cause legal issues for himself.

  • Bezier@suppo.fi
    cake
    link
    fedilink
    arrow-up
    15
    ·
    edit-2
    6 days ago

    The main event here was pretty interesting, but I’d just like to say that

    It asked me for my name and Whatsapp mobile number.

    Why not just the mobile number. Do they also operate drive-ins that only accept BMWs?

    • Mountaineer@aussie.zone
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      5 days ago

      In certain places like India, WhatsApp is the default means of communication for everyone.
      You can use it without phone data if you are on wifi, it supports better quality than sms for sending images, you can video chat with it, it’s cross platform, etc etc.

      What’s more amazing to me is that it’s not more popular in western countries.

        • Quail4789@lemmy.ml
          link
          fedilink
          English
          arrow-up
          12
          ·
          5 days ago

          unfortunately… noone seems to stop and think for a second why Meta would maintain an infrastructure/team, spending millions upon millions to provide a service that seemingly has no monetization built-in.

      • Bezier@suppo.fi
        cake
        link
        fedilink
        arrow-up
        6
        ·
        5 days ago

        I know it’s dominant, but it just sucks. To go back to the previous analogy, Whatsapp should have a monopoly on communication as much as BMW should have a monopoly on transportation.

      • Wave@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        Gonna be honest I’d much prefer Signal to take off in this regard. In the US iMessage is the closest widely excepted equivalent, but if I’m gonna do WiFi IM, I want to know it is 100% verifiably private. Otherwise I might as well be using SMS/MMS.

        • Mountaineer@aussie.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 days ago

          I agree and use Signal myself.
          But people like the extra features of WhatsApp like desktop/web clients with seamless history sync and all the other little things that WhatsApp provides.
          The average Joe doesn’t even think about security or privacy, they just know that the results of using WhatsApp are superior than using SMS.
          iMessage is a non starter everywhere out of the US, it just doesn’t have the market penetration.
          As an Australian, no one I know (many of whom own iPhones) talk about the blue-green bubble stuff.
          They recognise where the fault lies and simply don’t use the app.

          • Wave@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            4 days ago

            I know the average Joe doesnt care about security/privacy but, ugh. Really wish we did. Society (at least in the US, where I am) might be a bit less shit if they did. I’m glad to hear that iMessage is a flash in the pan in other countries though, I dont understand why its such a big deal here, especially when Signal/WhatsApp exists and provides a similar seemless experience across more than one platform, but then again you’d hear me complaining about Meta if I lived anywhere else in the world so, really a lose lose for me :(

            • Mountaineer@aussie.zone
              link
              fedilink
              English
              arrow-up
              2
              ·
              4 days ago

              I have a friend group that insist on all events being planned through facebook.
              I’ve missed out on events in the past due to not taking part.
              It’s no longer a hill I wish to die on.

  • ElectricMachman@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 days ago

    Brilliant article - but it looks like it’s now been removed. Would be impressive if someone at Dotpe got wind in such a short space of time…

    • poVoq@slrpnk.netOP
      link
      fedilink
      arrow-up
      7
      ·
      6 days ago

      Huh, it was still working when I posted it one hour ago… unlucky I guess 🤷‍♂️

  • EngineerGaming@feddit.nl
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    5 days ago

    It asked for your phone number? That is the thing that angered me the most. I wonder why you would share this rather than ask a waiter and say you don’t have Whatsapp, for example.